Could someone more knowledgeable explain why Non-resident passkeys need to have a username to make them work? Like, why can't the credential itself be it's own identifying factor if it's being generated deterministically anyway?
passkeys
OK my transfer from #Firefox to #Vivaldi now fully complete. No buyers remorse at all.
#Passkeys on every site you can, make everything so much better, btw
A few notes:
#Vivaldi after tweaking UX really can be a #Calmtech solution - at least as much as any browser can. But you can tweak EVERYTHING on it.
#Vivaldi's RSS feed feature - way more helpful than I thought.
#Already have about 10 ideas on how they could integrate the Fedi even more into the browser.
cc: @jon @brucelawson
Linux desktop question — I'd rather have data than my own assumptions.
A self-hosted service on your LAN asks you to create a passkey. What do you actually reach for?
Unlike macOS or Windows, a Linux desktop has no passkey store built into the OS — so it comes from somewhere else: a password manager extension, a hardware key, or your phone over the QR flow.
Tick everything you genuinely have available today.
(Asking because I'm building a self-hosted cluster thing and need to know what onboarding can safely assume.)
Options: (choose one or more)
🎉 Self-Hosted Human and Machine #Identity in #Keycloak 🎉
Our 26.4 release brings great updates with #passkeys and the latest security best practices for #OpenID Connect with #FAPI and DPoP.
Automatically roll out and rotate client credentials with #spiffe, #spire and #Kubernetes service account tokens.
Start your #sovereign journey and read all in our latest #cncf blog post:
https://www.cncf.io/blog/2025/11/07/self-hosted-human-and-machine-identities-in-keycloak-26-4/
So passkeys had a few moments in the media spotlight (in the UK) this week. I thought I'd revisit them to test them again.
For those who know the technology well, is there any mechanism for handling cross-device flows where bluetooth is unavailable? I can see it's meant to help with proximity checking... but I can't see a way to make it work without bluetooth in my (limited) tests.
Second, how can we make it work on a single machine with multiple browsers? e.g., Chromium and Firefox both installed, potentially with multiple profiles. A crude method is to install whichever FIDO2 authenticator/sync service on every ... single ... browser ... Better would be a cross-application flow on a single device.
Anyone able to point me to means of handling those use cases?